Pentest-Tools.com helps security professionals find, validate, and communicate vulnerabilities faster and with greater confidence - whether they’re internal teams defending at scale, MSPs juggling clients, or consultants under pressure.

With comprehensive coverage across network, web, API, and cloud assets, and built-in exploit validation, it turns every scan into credible, actionable insight.

Trusted by over 2,000 teams in 119 countries and used in more than 6 million scans annually, it delivers speed, clarity, and control - without bloated stacks or rigid workflows.


Pentest-Tools

New post: audit prep isn't mainly a documentation problem, it's a calendar problem.

50.7% of practitioners say getting time from technical teams is their biggest bottleneck. Jan Pedersen breaks down why in Office Hours #11, plus a live demo of scan diffs and evidence workflows.

Read it here: pentest-tools.com/blog/what-slows-down-audits

18 hours ago | [YT] | 0

Pentest-Tools

The US Department of Defense just credited Specter, our AI pentesting engine, with finding a vulnerability through HackerOne. 🎯

A successful AI pentest needs more than good prompts. Full story: pentest-tools.com/features/ai-pentests

1 day ago | [YT] | 2

Pentest-Tools

Cleaning up after AI is basically a job now. Who would have figured?
1 in 4 practitioners reworks more than 25% of what AI tools produce, according to our AI pentesting survey: pentest-tools.com/insights/ai-pentesting-survey

Does that track for you?

#offensivesecurity #cybersecurity #penetrationtesting

5 days ago | [YT] | 0

Pentest-Tools

Bucharest Cybersecurity Conference 2026 is where some of the sharpest offensive security conversations in the region happen, and that's the main reason we're contributing as Gold sponsors this year.

October 20-22, Bucharest. The Pentest-Tools.com team will be there talking AI pentesting, compliance, and reporting pressure. Autonomous AI agents in offensive operations are on this year's agenda too, so come find out how AI Pentests by Specter works.

Thanks to DNSC Romania for hosting.

Register: bcc.dnsc.ro/

6 days ago | [YT] | 1

Pentest-Tools

DEF CON asked how it works.
Black Hat asked what it proves.
Everyone asked: who sees the data?

That question gets to the heart of AI pentesting: trust.

Our answer:
βœ… frontier LLMs, run in the US
βœ… we validate exploits, not flag guesses
βœ… a decade of offensive security work, not a prompt wrapped in a UI

Robert Tanase and Jan Pedersen unpack what we learned at DEF CON and Black Hat, and what's next for AI Pentests, on our latest Office Hours.

Full recap and early access: pentest-tools.com/blog/ai-pentests-defcon-black-ha…

#offensivesecurity #penetrationtesting

1 week ago | [YT] | 0

Pentest-Tools

We surveyed 201 security and compliance practitioners on what audit cycles actually look like. Nearly 9 in 10 partially remap evidence by hand or re-document it per framework.

Free findings, no email required:
pentest-tools.com/insights/compliance-cycles-surve…

1 week ago | [YT] | 1

Pentest-Tools

At some point, one of these LLM choices became the tool you reach for without thinking. Let's settle it by vote.

Which LLM do you use for security testing activities?

1 week ago | [YT] | 1

Pentest-Tools

Last month we made a bit of history, and for once it wasn't a CVE. We were the first Romanian company ever to have a booth at DEF CON, showing AI Pentests, powered by Specter, to a room full of people whose entire job is finding what's wrong with things. Still in beta, early access is open now.

What else happened in August, you asked?

🎯 Sniper added a new exploit for CVE-2021-35464, a five-year-old RCE in Forgerock OpenAM that's still alive in the wild. As always, if Sniper can exploit it, the Network Scanner can detect it.
🌐 155 new detections in the Network Scanner, 70 of them critical, prioritized by CVSS, EPSS, and CISA KEV.
πŸ€– AI is picking up more of the boring work: the Password Auditor now finds stubborn login forms on its own, and our AI Ping Assistant moved from the website straight into the product.
πŸ”Œ The findings API can now update risk and verified status, findings carry a ransomware-campaign flag straight from CISA, and you can create your account in the US region if data residency matters to you.

Full breakdown in the changelog: pentest-tools.com/change-log
Early access to AI Pentests: pentest-tools.com/discover-ai-pentests

Until next time: stay sharp, stay human.

2 weeks ago | [YT] | 0

Pentest-Tools

If you've been here for a while, you know we're a very matter-of-fact team. That's why we'd rather *show* you what we build through *how it works* (aka results).

So today we're taking a moment to celebrate our latest bug bounty acknowledgements:

The #offensivesecurity logic behind AI Pentests has earned thanks from the U.S. Department of Defense, HPE, F5, phpBB, PepsiCo, and others through bug bounty programs.

Behind them are real reports we submitted to real programs based on work that requires

βœ… investigation,
βœ… reproducible evidence,
βœ… and clear impact.

This approach shapes every AI pentest:

follow the evidence β†’ validate exploitability β†’ document each step before a finding reaches the report.

Thank you to the program teams who reviewed and acknowledged AI Pentests!

See what we built + links to our bug bounty right here: pentest-tools.com/features/ai-pentests

2 weeks ago | [YT] | 3

Pentest-Tools

Oh, look, it's a fresh batch of CVEs that our #offensivesecurity research team found (and responsibly reported)!

They all impact SonicWall GMS, which SonicWall has now patched:

πŸ‘‰ CVE-2026-66147 - unauthenticated command injection in the Dispatcher Service, CVSS 9.4
πŸ‘‰ CVE-2026-66154 - weak certificate verification leading to user compromise via MitM, CVSS 8.3*
πŸ‘‰ CVE-2026-18634 - local privilege escalation via deserialization, CVSS 8.4

When it shortens 🀏 the distance between discovery and action - *that’s* what #vulnerabilityresearch does to help security teams.

Here's our team's latest disclosed contribution to the community: psirt.global.sonicwall.com/vuln-detail/SNWLID-2026…

And here's where you can get more of our research: pentest-tools.com/research

PS: More SonicWALL vulnerabilities coming soon to a research blog near you. 🫡

3 weeks ago | [YT] | 1